For downloadable software there is the risk of a supply chain attack. The website is altered to provide a download with a malware-infected version of the software.
See the recent hack on CPU-Z: https://gist.github.com/N3mes1s/b5b0b96782b9f832819d2db7c668...